Illegal website identification method and device, electronic device and storage medium
Through the communication connection between financial institutions and operators, the legitimacy of the website is judged by using the operator type and base station identification differences, which solves the problems of limited coverage and low accuracy of illegal website identification in existing technologies, and realizes efficient identification and fund protection without client tools.
Patent Information
- Application Number
- CN202210822348.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-13
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2042-07-13
AI Technical Summary
In the existing technology, illegal website identification relies on client tools, which have limited coverage and low accuracy. In addition, the mobile terminal lacks effective interception methods and cannot effectively identify illegal websites.
Establish a communication connection between financial institutions and operators to obtain customer login information for financial websites and terminals, use the differences in operator types and base station identifications to determine the legitimacy of the website, and combine the base station radiation distance and secondary authentication to determine whether the website is illegal.
It enables accurate identification of illegal websites without the need for client tools, improves recognition accuracy, prevents illegal tampering of the client, and protects the security of customer funds.
Smart Images

Figure CN115203611B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a method for identifying illegal websites, a device thereof, an electronic device, and a storage medium. Background Art
[0002] Currently, criminals often use various illegal websites to obtain customer information and then use this information to commit crimes, causing financial losses to customers. Related technologies often use tools such as enterprise controls, antivirus software, and browsers to identify illegal websites (or applications) and alert customers when they log in to suspected illegal websites.
[0003] However, the current identification of illegal websites relies on the customer's operation on the client side, and the success rate of judgment depends on the recognition model of tools such as browsers and anti-virus software, which has the following defects: (1) The identification of illegal websites cannot cover all illegal websites; (2) Existing browsers, anti-virus software and other tools are processed by different institutions, and the accuracy of identifying illegal websites is low; (3) Customers are required to install corresponding browsers, anti-virus software and other tools. If the recognition tools are not installed, they cannot be identified; (4) There is currently no effective interception method for mobile terminal (such as mobile phone) APP.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] The embodiments of the present invention provide a method for identifying illegal websites, a device thereof, an electronic device, and a storage medium, so as to at least solve the technical problem in related technologies that illegal websites need to be identified by relying on identification tools and the identification accuracy is low.
[0006] According to one aspect of an embodiment of the present invention, a method for identifying illegal websites is provided, in which a financial institution pre-establishes a communication connection with each operator, comprising: when a customer enters account information through a target website, based on the communication connection, obtaining financial website information for logging into the financial website with the account information, wherein the financial website is a website established by a financial institution, and the financial website information at least includes: a login operator type, a login base station identifier; when a fund transaction is conducted through the financial website, initiating a security authentication request, wherein the security authentication request is for performing a terminal verification code authentication on the financial website; based on the communication connection, obtaining terminal information of a terminal that sends or receives the terminal verification code, wherein the terminal information at least includes: a terminal operator type, a terminal base station identifier; when the login operator type is different from the terminal operator type, and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have no intersection, determining that the target website is an illegal website.
[0007] Optionally, the step of obtaining financial website information for logging into a financial website using the account information based on the communication connection includes: obtaining the operator type of the network accessed by the financial website; based on the operator type, selecting a target operator from the operator set indicated by the operator type through the communication connection to initiate a financial website information acquisition request, wherein the target operator returns the financial website information based on the financial website information acquisition request.
[0008] Optionally, after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, it also includes: when the login operator type is the same as the terminal operator type, judging whether the login base station identifier is the same as the terminal base station identifier; when the login base station identifier is the same as the terminal base station identifier, determining that the target website is the financial website, and executing the financial transaction.
[0009] Optionally, when the login operator type is the same as the terminal operator type, after determining whether the login base station identifier is the same as the terminal base station identifier, it also includes: when the login base station identifier is not the same as the terminal base station identifier, based on the communication connection, respectively obtaining the first radiation distance value of the first base station indicated by the login base station identifier and the second radiation distance value of the second base station indicated by the terminal base station identifier; determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value; when the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, determining that the target website is an illegal website.
[0010] Optionally, after determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, it also includes: when the distance value between the first base station and the second base station is less than or equal to the sum of the first radiation distance value and the second radiation distance value, initiating a secondary authentication request, wherein the secondary authentication request includes at least one of the following: face recognition, fingerprint recognition; if the secondary authentication request is passed, executing the financial transaction.
[0011] Optionally, after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, it also includes: when the login operator type is different from the terminal operator type, and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have an intersection, based on the communication connection, communicating with the login operator and the terminal operator respectively; obtaining the first physical position and third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtaining the second physical position and fourth radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator; based on the first physical position and the second physical position, determining whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value, determining that the target website is an illegal website; when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value, initiating a secondary authentication request.
[0012] Optionally, after determining that the target website is an illegal website, the method further includes: stopping the execution of the financial transaction and initiating an early warning notification.
[0013] According to another aspect of an embodiment of the present invention, a device for identifying illegal websites is also provided. A financial institution pre-establishes a communication connection with each operator, including: a first acquisition unit, used to obtain, based on the communication connection, financial website information of the financial website for logging into the financial website using the account information when a customer enters account information through a target website, wherein the financial website is a website established by a financial institution, and the financial website information at least includes: a login operator type and a login base station identifier; an initiating unit, used to initiate a security authentication request when conducting a fund transaction through the financial website, wherein the security authentication request is a terminal verification code authentication on the financial website; a second acquisition unit, used to obtain, based on the communication connection, terminal information of a terminal that sends or receives the terminal verification code, wherein the terminal information at least includes: a terminal operator type and a terminal base station identifier; a determination unit, used to determine that the target website is an illegal website when the login operator type is different from the terminal operator type and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have no intersection.
[0014] Optionally, the first acquisition unit includes: a first acquisition module, used to obtain the operator type of the financial website access network; a first initiation module, used to select a target operator from the operator set indicated by the operator type through the communication connection based on the operator type to initiate a financial website information acquisition request, wherein the target operator returns the financial website information based on the financial website information acquisition request.
[0015] Optionally, the identification device also includes: a first judgment module, used to determine whether the login base station identifier is the same as the terminal base station identifier after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, when the login operator type is the same as the terminal operator type; a first determination module, used to determine that the target website is the financial website and execute the financial transaction when the login base station identifier is the same as the terminal base station identifier.
[0016] Optionally, the identification device also includes: a second acquisition module, which is used to determine whether the login base station identifier and the terminal base station identifier are the same when the login operator type is the same as the terminal operator type, and when the login base station identifier and the terminal base station identifier are not the same, based on the communication connection, respectively obtain the first radiation distance value of the first base station indicated by the login base station identifier and the second radiation distance value of the second base station indicated by the terminal base station identifier; a second judgment module, which is used to determine whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value; a second determination module, which is used to determine that the target website is an illegal website when the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value.
[0017] Optionally, the identification device also includes: a second initiating module, used to initiate a secondary authentication request after determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, if the distance value between the first base station and the second base station is less than or equal to the sum of the first radiation distance value and the second radiation distance value, wherein the secondary authentication request includes at least one of the following: face recognition, fingerprint recognition; a first execution module, used to execute the financial transaction if the secondary authentication request is passed.
[0018] Optionally, the identification device also includes: a first communication module, which is used to communicate with the login operator and the terminal operator respectively based on the communication connection after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, when the login operator type is different from the terminal operator type and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have an intersection; a third acquisition module, which is used to obtain the first physical location and the third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtain the fourth base station indicated by the terminal base station identifier returned by the terminal operator. a second physical location of the station and a fourth radiation distance value; a third judgment module, used to judge whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value based on the first physical location and the second physical location; a third determination module, used to determine that the target website is an illegal website when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; a third initiation module, used to initiate a secondary authentication request when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value.
[0019] Optionally, the identification device further includes: a fourth initiating module, configured to stop executing the financial transaction and initiate an early warning notification after determining that the target website is an illegal website.
[0020] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method for identifying illegal websites.
[0021] According to another aspect of an embodiment of the present invention, an electronic device is also provided, comprising one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned method for identifying illegal websites.
[0022] In the present disclosure, when a customer enters account information through a target website, based on a communication connection, the financial website information of the financial website for logging in with the account information is obtained. When a fund transaction is conducted through the financial website, a security authentication request is initiated. Based on the communication connection, the terminal information of the terminal that sends or receives the terminal verification code is obtained. When the login operator type is different from the terminal operator type, and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not intersect, the target website is determined to be an illegal website. In the present application, the financial website information of the financial website for logging in with the current customer's account information and the terminal information of the terminal that sends or receives the terminal verification code can be obtained through the communication connection established between the financial institution and each operator. By comparing the financial website information with the terminal information, it can be determined whether the target website is safe, thereby realizing security authentication between enterprises and effectively preventing the client from being illegally tampered with. At the same time, the identification of illegal websites does not rely on tools such as controls and antivirus software, which is conducive to improving the recognition accuracy, thereby solving the technical problem in the related art that it is necessary to rely on recognition tools to identify illegal websites and the recognition accuracy is low. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0024] Figure 1 is a flow chart of an optional method for identifying illegal websites according to an embodiment of the present invention;
[0025] Figure 2 is a schematic diagram of an optional device for identifying illegal websites according to an embodiment of the present invention;
[0026] Figure 3 The figure is a hardware structure block diagram of an electronic device (or mobile device) for a method for identifying illegal websites according to an embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] To facilitate those skilled in the art to understand the present invention, some of the terms or nouns involved in the embodiments of the present invention are explained below:
[0030] Base station: The interface device through which mobile devices access the Internet.
[0031] Illegal website (phishing website): a fake website that deceives users.
[0032] It should be noted that the illegal website identification method and device disclosed in the present invention can be used in the field of information security when identifying illegal websites, and can also be used in any field other than the field of information security when identifying illegal websites. The application field of the illegal website identification method and device disclosed in the present invention is not limited.
[0033] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display and analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. For example, an interface is set up between this system and the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving the consent information fed back by the aforementioned user or organization.
[0034] The following embodiments of the present invention can be applied to various systems, applications, and devices for identifying illegal websites. This invention provides a method for identifying illegal websites based on inter-enterprise communication between telecommunications operators. By performing inter-enterprise authentication between telecommunications operators and financial institutions (or other institutions), the method effectively identifies whether a website is illegal and prevents illegal tampering with the client. The method also does not rely on tools such as controls and antivirus software for identification.
[0035] The present invention will be described in detail below with reference to various embodiments.
[0036] Example 1
[0037] According to an embodiment of the present invention, an embodiment of a method for identifying illegal websites is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0038] Figure 1 is a flow chart of an optional method for identifying illegal websites according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps:
[0039] Step S101, when the customer enters account information through the target website, based on the communication connection, obtains the financial website information for logging into the financial website using the account information, wherein the financial website is a website established by a financial institution, and the financial website information at least includes: login operator type, login base station identifier.
[0040] Step S102: Initiate a security authentication request when conducting a fund transaction through a financial website, wherein the security authentication request is a terminal verification code authentication on the financial website.
[0041] Step S103: Based on the communication connection, terminal information of the terminal that sends or receives the terminal verification code is obtained, wherein the terminal information at least includes: terminal operator type and terminal base station identifier.
[0042] Step S104: if the login operator type is different from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap, determine that the target website is an illegal website.
[0043] Through the above steps, when a customer enters account information through a target website, the financial website information of the account information used to log in to the financial website can be obtained based on the communication connection. When a financial transaction is conducted through the financial website, a security authentication request is initiated. Based on the communication connection, the terminal information of the terminal that sends or receives the terminal verification code is obtained. When the login operator type is different from the terminal operator type, and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not intersect, the target website is determined to be an illegal website. In an embodiment of the present invention, the financial website information of the current customer's account information used to log in to the financial website, as well as the terminal information of the terminal that sends or receives the terminal verification code, can be obtained through the communication connection established between the financial institution and each operator. By comparing the financial website information with the terminal information, it can be determined whether the target website is safe, thereby achieving inter-enterprise security authentication and effectively preventing the client from being illegally tampered with. At the same time, the identification of illegal websites does not rely on tools such as controls and antivirus software, which is conducive to improving the recognition accuracy, thereby solving the technical problem in the related art that it is necessary to rely on identification tools to identify illegal websites and the recognition accuracy is low.
[0044] The current process of illegal websites stealing customer funds is as follows: (1) Illegal personnel create illegal websites or illegal application APPs (can be referred to as illegal terminals) and disguise the illegal terminals as websites or application APPs of financial institutions (or other institutions); (2) Illegal personnel guide customers to click on illegal terminal links through web pages, text messages, etc.; (3) After the customer clicks on the illegal terminal link, the illegal personnel guide the customer to enter the account number, password, etc. to obtain the customer information, while the customer believes that he is logging into the financial institution website, which is actually an illegal terminal; (4) The illegal personnel enter the customer information on his own terminal, which is actually the illegal personnel interacting with the financial institution website; (5) The illegal personnel transfer the customer funds to his own account on the illegal terminal. At this time, security authentication is required, and the customer is guided to enter the terminal verification code; (6) The customer enters the terminal verification code on the illegal terminal, and the illegal personnel interacts with the financial institution on the illegal terminal through the illegal terminal verification code, and the funds are transferred.
[0045] Regarding the process of illegal websites stealing customer funds, the embodiment of the present invention can provide a detailed explanation of how to identify illegal websites in combination with the following steps.
[0046] Currently, under normal circumstances, the servers of illegal personnel are often registered overseas, which is very different from the geographical location of the customers. At the same time, the probability that the physical location of the device used by illegal personnel to log in to the financial institution's website (or application APP) is close to the physical location of the customer's terminal is extremely low. Therefore, the embodiment of the present invention can identify illegal websites based on the above situation.
[0047] In the embodiment of the present invention, the financial institution may establish communication connections with various operators in advance.
[0048] Step S101, when the customer enters account information through the target website, based on the communication connection, obtains the financial website information for logging into the financial website using the account information, wherein the financial website is a website established by a financial institution, and the financial website information at least includes: login operator type, login base station identifier.
[0049] Optionally, the step of obtaining financial website information for logging into a financial website using account information based on a communication connection includes: obtaining the operator type of the financial website access network; based on the operator type, selecting a target operator from the operator set indicated by the operator type through the communication connection to initiate a financial website information acquisition request, wherein the target operator returns the financial website information based on the financial website information acquisition request.
[0050] In an embodiment of the present invention, after the customer enters the account information through the target website, the customer can log in to the financial website through the account information. The financial institution can connect with the operator through a communication connection to record the financial website information of the financial website logged in by the customer's account information. The financial website information is the login operator type, the operator's specific base station number (i.e., the login base station identifier) and other information provided by the operator. Specifically, the operator type of the financial website access network can be obtained first. Based on the operator type, through the corresponding communication connection, the target operator in the operator set indicated by the operator type is selected to initiate a financial website information acquisition request. After receiving the financial website information acquisition request, the target operator can return the financial website information of the financial website logged in by the current account information.
[0051] Step S102: Initiate a security authentication request when conducting a fund transaction through a financial website, wherein the security authentication request is a terminal verification code authentication on the financial website.
[0052] In an embodiment of the present invention, if a financial website conducts a financial transaction after logging into a customer account using account information, the financial website will initiate a security authentication request, which is a terminal verification code authentication on the financial website. For example, the financial website sends the verification code to the terminal number bound to the current customer account, or the terminal bound to the current customer account sends the verification code displayed by the financial website to a designated number, etc.
[0053] Step S103: Based on the communication connection, terminal information of the terminal that sends or receives the terminal verification code is obtained, wherein the terminal information at least includes: terminal operator type and terminal base station identifier.
[0054] In an embodiment of the present invention, a financial institution can, based on a communication connection, request an information receipt (i.e., the terminal information of the terminal that sends or receives the terminal verification code) from the operator through downlink (or uplink) information (i.e., the financial website sends information to the bound terminal number or the bound terminal sends the verification code displayed by the financial website to the designated number). The information receipt can record the terminal operator type, terminal base station identifier, etc.
[0055] Optionally, after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, it also includes: when the login operator type is the same as the terminal operator type, judging whether the login base station identifier is the same as the terminal base station identifier; when the login base station identifier is the same as the terminal base station identifier, determining that the target website is a financial website and executing the financial transaction.
[0056] In an embodiment of the present invention, the operator of the customer who receives the information (i.e., the terminal operator type) may be inconsistent with the operator who logs in to the financial website (i.e., the login operator type). Therefore, it is possible to first distinguish whether the login operator type is the same as the terminal operator type. When the login operator type is the same as the terminal operator type, it is possible to determine whether the login base station identifier is the same as the terminal base station identifier. If the base station identifiers are the same, it is determined that the customer has not logged in to a non-illegal website to conduct transactions (i.e., the target website is determined to be a financial website), the transaction is normal, and the financial transaction can be executed.
[0057] Optionally, when the login operator type is the same as the terminal operator type, after determining whether the login base station identifier is the same as the terminal base station identifier, it also includes: when the login base station identifier is not the same as the terminal base station identifier, based on the communication connection, respectively obtaining the first radiation distance value of the first base station indicated by the login base station identifier and the second radiation distance value of the second base station indicated by the terminal base station identifier; determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value; when the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, determining that the target website is an illegal website.
[0058] In an embodiment of the present invention, when the login base station identifier and the terminal base station identifier are different, the financial institution can interact with the corresponding operator based on the communication connection to determine whether the distance between the two base stations is greater than the sum of the radiation ranges of the two base stations. Specifically, the first radiation distance value of the first base station indicated by the login base station identifier and the second radiation distance value of the second base station indicated by the terminal base station identifier can be obtained first, and then it can be determined whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value. If it is greater, the transaction is determined to be abnormal (that is, the target website is determined to be an illegal website, not a financial website).
[0059] Optionally, after determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, it also includes: when the distance value between the first base station and the second base station is less than or equal to the sum of the first radiation distance value and the second radiation distance value, initiating a secondary authentication request, wherein the secondary authentication request includes at least one of the following: face recognition, fingerprint recognition; if the secondary authentication request is passed, executing the financial transaction.
[0060] In an embodiment of the present invention, when the distance value between the first base station and the second base station is less than or equal to the sum of the first radiation distance value and the second radiation distance value, the transaction can be determined to be suspicious, and a secondary authentication request can be initiated on the financial website. For example, secondary authentication such as face recognition and fingerprint recognition can be performed, and different processing can be performed according to the specific situation. There is no restriction here. If the secondary authentication request is passed, the financial transaction can continue.
[0061] Optionally, after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, it also includes: when the login operator type is different from the terminal operator type, and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier overlap, communicating with the login operator and the terminal operator respectively based on the communication connection; obtaining the first physical position and third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtaining the second physical position and fourth radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator; based on the first physical position and the second physical position, determining whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value, determining that the target website is an illegal website; when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value, initiating a secondary authentication request.
[0062] In an embodiment of the present invention, if the login operator type is different from the terminal operator type, but the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier overlap, then based on the communication connection, the financial institution can communicate with the login operator and the terminal operator respectively, obtain the first physical position and third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtain the second physical position and fourth radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator. After that, it is determined whether the distance between the two base stations is greater than the sum of the radiation ranges of the two base stations (that is, whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value). If so, the transaction is determined to be abnormal (that is, when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value, the target website is determined to be an illegal website). If not, the transaction is determined to be suspicious (that is, when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value, a secondary authentication request is initiated).
[0063] Step S104: if the login operator type is different from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap, determine that the target website is an illegal website.
[0064] In an embodiment of the present invention, if the login operator type and the terminal operator type and the coverage ranges of the base stations indicated by different login base station identifiers and the base stations indicated by the terminal base station identifiers have no intersection (for example, the two base stations are located in different countries), this situation can be determined as a transaction abnormality and the target website can be determined to be an illegal website.
[0065] Optionally, after determining that the target website is an illegal website, the method further includes: stopping the execution of fund transactions and initiating an early warning notification.
[0066] In an embodiment of the present invention, after determining that the target website is an illegal website, the execution of the financial transaction can be stopped in time and an early warning notification can be initiated. For example, after determining that the transaction is abnormal, the financial institution can freeze the transaction and remind the customer to go to the financial institution to unfreeze it on site by phone or text message. After the login password is modified after manual authentication by staff, the customer account can be used to log in again, which can effectively prevent the customer from suffering financial losses.
[0067] In an embodiment of the present invention, through an anti-illegal identification method for inter-enterprise communication based on a communication operator, financial institutions (or other institutions) and operators can provide a basis for determining whether a website is illegal, which can effectively avoid interference caused by illegal personnel tampering with client data. Financial institutions can determine potential illegal risks through interaction with operators, avoid financial losses for customers, and are conducive to improving the image of financial institutions and effectively combating Internet fraud crimes.
[0068] The present invention is described below in conjunction with another optional embodiment.
[0069] Example 2
[0070] The illegal website identification device provided in this embodiment includes multiple implementation units, each implementation unit corresponding to each implementation step in the above-mentioned embodiment 1.
[0071] Figure 2 is a schematic diagram of an optional device for identifying illegal websites according to an embodiment of the present invention. Figure 2 As shown, the identification device may include: a first acquisition unit 20, an initiating unit 21, a second acquisition unit 22, and a determining unit 23, wherein:
[0072] The first acquisition unit 20 is configured to acquire, based on the communication connection, financial website information for logging into a financial website using the account information when the customer enters the account information through the target website, wherein the financial website is a website established by a financial institution, and the financial website information includes at least a login operator type and a login base station identifier;
[0073] The initiating unit 21 is configured to initiate a security authentication request when conducting a fund transaction through a financial website, wherein the security authentication request is a terminal verification code authentication on the financial website;
[0074] The second acquiring unit 22 is configured to acquire terminal information of a terminal that sends or receives a terminal verification code based on the communication connection, wherein the terminal information includes at least: a terminal operator type and a terminal base station identifier;
[0075] The determining unit 23 is configured to determine that the target website is an illegal website when the login operator type is different from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap.
[0076] The identification device can obtain, through a first acquisition unit 20, financial website information of the financial website used to log in to the account information when a customer enters account information through a target website, based on a communication connection. The initiation unit 21 can initiate a security authentication request when a financial transaction is conducted through the financial website. The second acquisition unit 22 can obtain, through a communication connection, terminal information of the terminal that sends or receives the terminal verification code. The determination unit 23 can determine that the target website is an illegal website when the login operator type and the terminal operator type are different and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap. In an embodiment of the present invention, the financial website information of the financial website used to log in to the customer's account information and the terminal information of the terminal that sends or receives the terminal verification code can be obtained through a communication connection established between a financial institution and each operator. By comparing the financial website information with the terminal information, the security of the target website can be determined, thereby achieving inter-enterprise security authentication and effectively preventing illegal tampering of the client. Furthermore, the identification of illegal websites does not rely on tools such as control panels and antivirus software, which is conducive to improving the recognition accuracy rate, thereby solving the technical problem of relying on recognition tools to identify illegal websites in related technologies and having low recognition accuracy.
[0077] Optionally, the first acquisition unit includes: a first acquisition module, used to obtain the operator type of the financial website access network; a first initiation module, used to select a target operator from the operator set indicated by the operator type through a communication connection based on the operator type to initiate a financial website information acquisition request, wherein the target operator returns the financial website information based on the financial website information acquisition request.
[0078] Optionally, the identification device also includes: a first judgment module, used to determine whether the login base station identifier and the terminal base station identifier are the same after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, when the login operator type is the same as the terminal operator type; a first determination module, used to determine that the target website is a financial website and execute a financial transaction when the login base station identifier is the same as the terminal base station identifier.
[0079] Optionally, the identification device also includes: a second acquisition module, which is used to determine whether the login base station identifier and the terminal base station identifier are the same when the login operator type and the terminal operator type are the same; and when the login base station identifier and the terminal base station identifier are not the same, based on the communication connection, respectively obtain the first radiation distance value of the first base station indicated by the login base station identifier and the second radiation distance value of the second base station indicated by the terminal base station identifier; a second judgment module, which is used to determine whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value; and a second determination module, which is used to determine that the target website is an illegal website when the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value.
[0080] Optionally, the identification device also includes: a second initiating module, used to initiate a secondary authentication request after determining whether the distance value between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, when the distance value between the first base station and the second base station is less than or equal to the sum of the first radiation distance value and the second radiation distance value, wherein the secondary authentication request includes at least one of the following: face recognition, fingerprint recognition; a first execution module, used to execute the financial transaction if the secondary authentication request is passed.
[0081] Optionally, the identification device also includes: a first communication module, which is used to communicate with the login operator and the terminal operator respectively based on the communication connection after obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, when the login operator type is different from the terminal operator type and the coverage range between the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier overlap; a third acquisition module, which is used to obtain the first physical position and third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtain the second physical position and fourth radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator; a third judgment module, which is used to judge whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value based on the first physical position and the second physical position; a third determination module, which is used to determine that the target website is an illegal website when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; a third initiation module, which is used to initiate a secondary authentication request when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value.
[0082] Optionally, the identification device further includes: a fourth initiating module, configured to stop executing the financial transaction and initiate an early warning notification after determining that the target website is an illegal website.
[0083] The above-mentioned identification device may also include a processor and a memory. The above-mentioned first acquisition unit 20, initiating unit 21, second acquisition unit 22, determination unit 23, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize corresponding functions.
[0084] The processor includes a kernel that retrieves corresponding program units from a memory. One or more kernels may be configured to adjust kernel parameters to determine that a target website is an illegal website when the login operator type differs from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier do not overlap with the coverage areas of the base station indicated by the terminal base station identifier.
[0085] The above-mentioned memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0086] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing an initialization program having the following method steps: when a customer enters account information through a target website, based on a communication connection, obtaining the financial website information for logging into the financial website with the account information; when a fund transaction is conducted through the financial website, initiating a security authentication request; based on the communication connection, obtaining the terminal information of the terminal that sends or receives the terminal verification code; when the login operator type is different from the terminal operator type, and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have no intersection, determining that the target website is an illegal website.
[0087] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method for identifying illegal websites.
[0088] According to another aspect of an embodiment of the present invention, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement the above-mentioned method for identifying illegal websites.
[0089] Figure 3 FIG. 1 is a hardware structure diagram of an electronic device (or mobile device) for an illegal website identification method according to an embodiment of the present invention. Figure 3As shown, the electronic device may include one or more (illustrated as 302a, 302b, ..., 302n in the figure) processors 302 (the processor 302 may include but is not limited to a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 304 for storing data. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a keyboard, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 3 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 3 More or fewer components than shown, or with Figure 3 Different configurations shown.
[0090] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0091] In the above embodiments of the present invention, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0092] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0093] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0094] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0095] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc. Various media that can store program codes.
[0096] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A method for identifying illegal websites, characterized in that: Financial institutions establish communication connections with various operators in advance, including: When the customer enters account information through the target website, obtaining, based on the communication connection, financial website information for logging into a financial website using the account information, wherein the financial website is a website established by a financial institution, and the financial website information includes at least: a login operator type and a login base station identifier; Initiating a security authentication request when conducting a fund transaction through the financial website, wherein the security authentication request is to perform a terminal verification code authentication on the financial website; wherein the terminal verification code authentication refers to the financial website sending a verification code to the terminal number bound to the current customer account, or the terminal bound to the current customer account sending the verification code displayed on the financial website to a designated number; Based on the communication connection, obtaining terminal information of the terminal that sends or receives the terminal verification code, wherein the terminal information at least includes: terminal operator type and terminal base station identifier; In a case where the login operator type is different from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap, determining that the target website is an illegal website; After obtaining the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, it also includes: when the login operator type is different from the terminal operator type and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier overlap, based on the communication connection, communicating with the login operator and the terminal operator respectively; obtaining the first physical position and third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and obtaining the second physical position and fourth radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator; based on the first physical position and the second physical position, determining whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value, determining that the target website is an illegal website; when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value, initiating a secondary authentication request.
2. The identification method according to claim 1, characterized in that The step of obtaining the financial website information for logging into the financial website using the account information based on the communication connection includes: Obtaining the operator type of the network accessed by the financial website; Based on the operator type, a target operator from the operator set indicated by the operator type is selected through the communication connection to initiate a financial website information acquisition request, wherein the target operator returns the financial website information based on the financial website information acquisition request.
3. The identification method according to claim 1, characterized in that After acquiring the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, the method further includes: In a case where the login operator type is the same as the terminal operator type, determining whether the login base station identifier is the same as the terminal base station identifier; In a case where the login base station identifier is identical to the terminal base station identifier, the target website is determined to be the financial website, and the fund transaction is performed.
4. The identification method according to claim 3, characterized in that In a case where the login operator type is the same as the terminal operator type, after determining whether the login base station identifier is the same as the terminal base station identifier, the method further includes: When the login base station identifier is different from the terminal base station identifier, based on the communication connection, respectively obtaining a first radiation distance value of a first base station indicated by the login base station identifier and a second radiation distance value of a second base station indicated by the terminal base station identifier; Determining whether the distance between the first base station and the second base station is greater than the sum of the first radiation distance and the second radiation distance; When the distance between the first base station and the second base station is greater than the sum of the first radiation distance and the second radiation distance, the target website is determined to be an illegal website.
5. The identification method according to claim 4, characterized in that: After determining whether the distance between the first base station and the second base station is greater than the sum of the first radiation distance value and the second radiation distance value, the method further includes: Initiate a secondary authentication request when the distance between the first base station and the second base station is less than or equal to the sum of the first radiation distance and the second radiation distance, wherein the secondary authentication request includes at least one of the following: face recognition and fingerprint recognition; If the secondary authentication request is passed, the fund transaction is executed.
6. The identification method according to claim 1, characterized in that After determining that the target website is an illegal website, the method further includes: Stop executing the fund transaction and initiate an early warning notification.
7. A device for identifying illegal websites, characterized in that: Financial institutions establish communication connections with various operators in advance, including: a first acquiring unit configured to acquire, based on the communication connection, financial website information for logging into a financial website using the account information when the customer enters the account information through the target website, wherein the financial website is a website established by a financial institution, and the financial website information includes at least a login operator type and a login base station identifier; an initiating unit, configured to initiate a security authentication request when conducting a fund transaction through the financial website, wherein the security authentication request is terminal verification code authentication on the financial website; wherein the terminal verification code authentication refers to the financial website sending a verification code to a terminal number bound to the current customer account, or the terminal bound to the current customer account sending a verification code displayed on the financial website to a designated number; A second acquiring unit is configured to acquire, based on the communication connection, terminal information of a terminal that sends or receives the terminal verification code, wherein the terminal information includes at least: a terminal operator type and a terminal base station identifier; a determining unit, configured to determine that the target website is an illegal website if the login operator type is different from the terminal operator type and the coverage areas of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier do not overlap; The identification device also includes: a first communication module for communicating with the login operator and the terminal operator respectively based on the communication connection after acquiring the terminal information of the terminal that sends or receives the terminal verification code based on the communication connection, when the login operator type is different from the terminal operator type and the coverage ranges of the base station indicated by the login base station identifier and the base station indicated by the terminal base station identifier have an intersection; a third acquisition module for acquiring the first physical location and the third radiation distance value of the third base station indicated by the login base station identifier returned by the login operator, and acquiring the first physical location and the third radiation distance value of the fourth base station indicated by the terminal base station identifier returned by the terminal operator. a second physical location and a fourth radiation distance value; a third judgment module, used to judge whether the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value based on the first physical location and the second physical location; a third determination module, used to determine that the target website is an illegal website when the distance value between the third base station and the fourth base station is greater than the sum of the third radiation distance value and the fourth radiation distance value; a third initiation module, used to initiate a secondary authentication request when the distance value between the third base station and the fourth base station is less than or equal to the sum of the third radiation distance value and the fourth radiation distance value.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for identifying illegal websites according to any one of claims 1 to 6.
9. An electronic device, characterized in that: The invention comprises one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method for identifying illegal websites as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Method for identifying unauthorized access of an account of an online service
CN107548547A
Verification code anti-theft method and device, and network device
CN108600215A